Role description
Job Description – GRC (Governance, Risk & Compliance) Analyst / Senior AnalystExperience
- 3–5 years or 5–8 years of relevant experience in Governance, Risk & Compliance (GRC), IT Risk, or IT Compliance.
Role Summary
We are seeking a GRC professional with strong expertise in IT governance, risk management, compliance frameworks, and control assessment. The ideal candidate will work closely with business and technology teams to strengthen the organization's compliance posture, manage risks, and support audit readiness through effective policy, control, and governance practices.
Must-Have Skills
- 3–8 years of experience in IT Governance, Risk & Compliance (GRC), IT Risk, or IT Compliance.
- Strong understanding of industry compliance frameworks and regulatory standards such as NIST, ISO 27001, SOC 2, GovRAMP, and other relevant security/compliance frameworks.
- Experience performing risk assessments, including issue and exception management, evaluating compensating controls, and determining residual risk.
- Hands-on experience with IT control testing, including identifying appropriate audit evidence, validating control effectiveness, and supporting internal/external audits.
- Experience developing and maintaining security policies, standards, procedures, and controls that are measurable, actionable, and aligned with business and regulatory requirements.
- Strong knowledge of IT governance, risk management methodologies, and compliance best practices.
- Excellent written and verbal communication skills, with the ability to communicate effectively with both business stakeholders and technical teams.
- Strong analytical, documentation, and stakeholder management skills.
Good-to-Have Skills
- Experience supporting SOC 2, ISO 27001, GovRAMP, or similar certification and audit programs.
- Exposure to GRC platforms such as Archer, ServiceNow GRC, OneTrust, AuditBoard, or similar tools.
- Knowledge of cloud security and compliance (AWS, Azure, or GCP).
- Experience working with cross-functional teams in a fast-paced enterprise environment.
- Relevant certifications such as CISA, CRISC, CISSP, ISO 27001 Lead Implementer/Lead Auditor, or equivalent are preferred.
Key Responsibilities
- Conduct IT risk assessments and compliance reviews across business and technology environments.
- Manage compliance issues and exceptions by assessing risks, reviewing compensating controls, and documenting residual risk.
- Perform and coordinate IT control testing, ensuring evidence collected is sufficient and audit-ready.
- Develop, review, and maintain security policies, standards, procedures, and control documentation.
- Support internal and external audits by providing accurate documentation and responding to audit requests.
- Partner with business and technology stakeholders to ensure compliance with organizational policies and regulatory requirements.
- Track remediation activities and monitor compliance with established controls and governance processes.
- Drive continuous improvement in governance, risk, and compliance practices across the organization.
Skills
Compliance Management, NIST 800-53, GovRAMP, SOC 2
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.